Home Log in

Privacy Policy

Effective 5 August 2026 ยท Version 1.1

SuiteMate is job-management software for trade and construction businesses. This policy explains what personal information we collect, why we collect it, who we share it with, and what you can do about it. It is written to be read, not to be survived.

Please note: this policy describes how SuiteMate actually works and is kept current with the product. It has been prepared in good faith but has not yet been reviewed by a lawyer. If anything here is unclear or appears inconsistent with your experience of the app, please tell us โ€” we would rather fix it than defend it.

1. Who we are

SuiteMate is operated by Fermiware Pty Ltd (ABN 78 699 924 475), an Australian proprietary limited company registered in New South Wales. In this policy, "we", "us" and "our" mean Fermiware Pty Ltd, and "SuiteMate" means our web application at app.suitemate.com.au and our website at suitemate.com.au.

Our registered office is 7 Conley Avenue, Lake Conjola NSW 2539, Australia.

We are bound by the Privacy Act 1988 (Cth) and the Australian Privacy Principles (APPs). Some small businesses are exempt from the Privacy Act, but we have chosen to comply regardless, because our customers trust us with information about their own clients and workers.

2. Two different roles โ€” and why it matters

SuiteMate handles two quite different categories of information, and our obligations differ for each. This distinction runs through the rest of this policy, so it is worth getting straight up front.

CategoryExampleOur role
Account information Your name, email, company details, billing records We decide how it is used. We are the controller.
Customer data Your clients, your workers, your quotes, your job sites You decide how it is used. We only hold and process it on your instructions. We are the processor.

In plain terms: the records you put into SuiteMate remain yours. We do not sell them, mine them, or use them to build products. If one of your clients asks us what we hold about them, we will direct them to you, because you are the business they dealt with โ€” not us.

3. What we collect

3.1 Account and identity information

3.2 Billing information

We never see or store your card number. Card details are entered directly into Stripe's hosted checkout and never touch our servers. We receive only a token and the last four digits.

3.3 Customer data you enter

This is the substance of what SuiteMate stores, and it is genuinely sensitive โ€” it describes other people, most of whom have no direct relationship with us:

3.4 Technical information

3.5 Mobile app information

The SuiteMate mobile app collects three things the website does not. Each one is asked for at the moment it is needed, and each can be refused.

Clock-on locations are visible to the business that employs the worker โ€” that is the point of recording them. They are not shared with anyone else, and they are never sold or used for advertising. The app contains no advertising, no analytics profiling and no cross-app tracking.

3.6 Sensitive information

We do not ask for sensitive information as defined by the Privacy Act (such as health, racial or ethnic origin, political opinions, religious beliefs, or criminal record). SuiteMate has no fields designed to hold it.

However, free-text fields โ€” job notes, checklist notes, messages โ€” will accept whatever is typed into them. Please do not record sensitive personal information in free-text fields, such as a worker's medical details or an incident involving someone's health. If you need to store that kind of record, use a system built for it.

4. How we collect it

Where we collect information about a person from you rather than from them โ€” your clients and your workers, for instance โ€” you are responsible for having told them that you use a system like SuiteMate, and for having any consent required. We provide the tooling; the relationship is yours.

5. Why we use it

We use personal information only for purposes connected with running the service:

What we do not do: we do not sell personal information. We do not share it with advertisers or data brokers. We do not use your customer data to train machine-learning models. We do not read your records except where strictly necessary to fix a fault you have reported, respond to a security incident, or comply with the law.

6. Who we share it with

SuiteMate is built on infrastructure operated by other companies. Each is bound by its own contractual and privacy obligations, and each receives only what it needs.

ProviderPurposeWhat it receives
SupabaseDatabase, authentication and file storageAll application data, including customer data and attachments
VercelApplication hosting and deliveryRequests, IP addresses and server logs
StripeSubscription billing, and card payments on your invoices where you enable themBilling contact details and payment records. Card data goes directly to Stripe.
ResendSending emailRecipient addresses and the content of messages sent through SuiteMate
TwilioSending SMSRecipient mobile numbers and message content
XeroAccounting synchronisation, only if you connect itContacts, invoices and payment records you choose to sync
Fair Work Commission APIRetrieving current award pay ratesAward and classification lookups only โ€” no personal information
Australian Business RegisterABN validationABN lookups only

We may also disclose personal information:

7. Overseas disclosure

Your application data โ€” including all customer data โ€” is stored in Sydney, Australia (AWS ap-southeast-2).

Some of our providers are headquartered overseas, principally in the United States, and their support and engineering staff may access systems from outside Australia. In particular, Stripe, Resend, Twilio, Vercel and Xero each operate internationally. By using SuiteMate you consent to this disclosure. We take reasonable steps to ensure each provider handles information consistently with the Australian Privacy Principles, but we cannot control every practice of an overseas recipient, and APP 8.1 may not apply to all of them.

8. Where it lives and how it's protected

We take security seriously, and some of the measures are structural rather than merely procedural:

No system is perfectly secure, and we will not pretend otherwise. If you discover a vulnerability, please report it to us โ€” see section 15. We will not pursue action against anyone who reports a genuine security issue in good faith and does not exploit it or access other users' data.

9. How long we keep it

10. Your rights

Under the Australian Privacy Principles you may:

Most of these you can do yourself inside the app. For anything else, contact us and we will respond within 30 days. We do not charge for access requests. If we refuse a request, we will tell you why in writing.

If you are a client or worker of a SuiteMate customer โ€” that is, your details are in the system because a business you dealt with put them there โ€” please contact that business directly. They control those records. We will assist them in responding, but we cannot alter or release their data on your behalf.

11. Cookies and tracking

SuiteMate uses cookies and similar browser storage strictly for operation:

We do not use advertising or third-party tracking cookies, and we do not run analytics that profile individuals across sites. Blocking essential cookies will prevent you logging in.

12. Data breaches

We are subject to the Notifiable Data Breaches scheme under Part IIIC of the Privacy Act. If a breach occurs that is likely to result in serious harm, we will notify affected individuals and the Office of the Australian Information Commissioner as soon as practicable.

Where the breach involves data belonging to one of our customers, we will notify that customer promptly and give them the information they need to meet their own notification obligations.

13. Children

SuiteMate is business software and is not directed at children. We do not knowingly collect information from anyone under 16 as an account holder. Where a customer records a young apprentice as a worker, that record is customer data under section 2 and the employing business is responsible for it.

14. Changes to this policy

We may update this policy as the product changes or the law does. The effective date at the top always reflects the current version. For material changes โ€” a new category of data, a new disclosure, a new overseas recipient โ€” we will give you at least 30 days' notice by email or in-app before the change takes effect.

15. Contact and complaints

To make a privacy request, ask a question, or report a security issue:

We will acknowledge a complaint within 5 business days and respond substantively within 30 days.

If you are not satisfied with our response, you may complain to the Office of the Australian Information Commissioner: oaic.gov.au, 1300 363 992, or GPO Box 5218, Sydney NSW 2001.

Read our Terms of Service โ†’